ZDI-CAN-26574: ZDI-25-1057: (0Day) Microsoft Visual Studio VsDevCmd Uncontrolled Search Path Element Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Visual Studio. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26574?
ZDI-CAN-26574 has a CVSS score indicating a high severity vulnerability that can lead to remote code execution.
How do I fix ZDI-CAN-26574?
To mitigate ZDI-CAN-26574, update Microsoft Visual Studio to the latest version provided by Microsoft.
What software is affected by ZDI-CAN-26574?
ZDI-CAN-26574 specifically affects Microsoft Visual Studio installations.
What type of attack does ZDI-CAN-26574 involve?
ZDI-CAN-26574 allows remote attackers to execute arbitrary code, requiring user interaction through malicious pages or files.
Is user interaction necessary for ZDI-CAN-26574 exploitation?
Yes, user interaction is required for exploiting ZDI-CAN-26574 by visiting a malicious page or opening a malicious file.